ServicesHow It WorksIndustriesResultsInsightsReactivate My List
Consent Requirements

Is it illegal to send promotional emails?

Back to InsightsIs it illegal to send promotional emails?

Is it illegal to send promotional emails?

Key Facts

  • ["Verkada paid $2.95 million in 2024—the largest CAN-SPAM settlement in FTC history—for sending 30 million emails with no opt-out", "https://www.inboxarmy.com/blog/email-marketing-laws-every-marketer-needs-to-know-in-2026/"], ["GDPR fines exceeded €1.2 billion in one year, with maximum penalties up to €20 million or 4% of global revenue", "https://www.mailforge.ai/blog/gdpr-vs-can-spam"], ["CASL allows fines of up to $10 million CAD per violation for organizations, and individuals can sue directly", "https://www.inboxarmy.com/blog/email-marketing-laws-every-marketer-needs-to-know-in-2026/"], ["Under CAN-SPAM, the FTC updated the fine to $53,088 per violating email in January 2025—not per campaign", "https://www.inboxarmy.com/blog/email-marketing-laws-every-marketer-needs-to-know-in-2026/"], ["Since February 2024, Gmail has permanently rejected bulk senders who fail email authentication or lack a one-click unsubscribe", "https://www.inboxarmy.com/blog/email-marketing-laws-every-marketer-needs-to-know-in-2026/"], ["Over 300 CAN-SPAM cases have been filed with the FTC to date", "https://www.inboxarmy.com/blog/email-marketing-laws-every-marketer-needs-to-know-in-2026/"], ["Experian settled for $650,000 due to a broken unsubscribe flow during a platform migration", "https://www.inboxarmy.com/blog/email-marketing-laws-every-marketer-needs-to-know-in-2026/"]]

Many US business owners assume that because CAN-SPAM permits unsolicited commercial email, they can send promotional messages freely. That assumption is expensive: the law allows sending first, but it demands strict requirements in every message, and the penalties are severe.

Under CAN-SPAM, you don't need consent before emailing a US recipient — but every commercial email must meet seven specific requirements, including accurate sender information, no deceptive subject lines, a valid physical postal address, and a functional unsubscribe mechanism. You must honor opt-out requests within 10 business days, keep the unsubscribe option valid for at least 30 days after sending, and never charge a fee or require a login to process an opt-out, per FTC guidance. You also remain legally responsible even when a third-party vendor sends the campaign on your behalf, as legal analysis of email and text compliance makes clear.

The penalties scale in a way most owners don't expect. The FTC updated the fine in January 2025 to $53,088 per violating email — not per campaign, per individual message, according to email marketing law research. A 10,000-recipient campaign sent without a working opt-out could theoretically expose a business to over $500 million in penalties, one comparison of GDPR and CAN-SPAM notes. Enforcement is real, not theoretical:

  • Verkada paid $2.95 million in 2024 — the largest CAN-SPAM settlement in FTC history — for sending 30 million emails over three years with no opt-out, no physical address, and ignored unsubscribe requests.
  • Experian settled for $650,000 because a broken unsubscribe flow during a platform migration went unnoticed.
  • Over 300 CAN-SPAM cases have been filed with the FTC to date.

Notably, neither company set out to break the law. Experts observing these cases describe them as operational blind spots — compliance gaps that quietly develop during a redesign or email platform switch when nobody is specifically watching.

Here's the part that catches US businesses off guard: the applicable law follows the recipient, not your company address. A US business emailing someone in Germany must comply with GDPR for that contact, and GDPR requires explicit opt-in consent before anything is sent — with fines up to €20 million or 4% of global revenue. A recipient in Canada triggers CASL, which carries penalties up to $10 million CAD per violation. Where your office sits is irrelevant, which is why segmenting your list by recipient location matters.

This is why CallMyCustomers works only from lists of real customers with every message approved by the owner first — reactivating people who already know your business is both the most profitable and the most defensible place to run outreach. If you'd like a free review of what your customer list could produce, with your rate and setup quoted upfront, start with the insights hub and see how a permission-based reactivation campaign fits your repeat-revenue cycle.

Sending promotional emails without proper consent isn't just risky—it's illegal in many parts of the world. Laws like GDPR in the EU, CASL in Canada, and PECR in the UK require businesses to obtain explicit opt-in permission before sending marketing messages to recipients in those regions. This means a U.S.-based company emailing someone in Germany must comply with GDPR for that recipient, regardless of where the sender is located. The law follows your recipient, not your company address, making geographic compliance essential for any business with international contacts.

For CallMyCustomers, which helps U.S. service businesses reactivate past customers through approved email and text campaigns, this means ensuring consent standards are met based on where each recipient resides. Under GDPR, fines can reach up to €20 million or 4% of global annual revenue—whichever is higher—for violations involving improper consent. GDPR fines exceeded €1.2 billion in one year, demonstrating how seriously regulators treat consent breaches. Similarly, CASL in Canada allows fines of up to $10 million CAD per violation for organizations, with individuals even able to sue directly for non-compliance. These penalties aren't theoretical; they've been enforced against major companies for failures like missing unsubscribe options or using deceptive tactics.

  • GDPR requires "clear, affirmative action" for consent—pre-checked boxes are prohibited under EU law.
  • CASL mandates express consent that doesn't expire unless the recipient withdraws it, unlike implied consent which fades after six months to two years.
  • PECR in the UK aligns closely with GDPR, requiring opt-in for promotional emails and enforcing fines through the Information Commissioner's Office.

Even if a business operates solely in the U.S., emailing international customers triggers these stricter consent rules. Ignoring them risks not only financial penalties but also deliverability issues, as platforms like Gmail now block senders who fail authentication or lack a working one-click unsubscribe—standards that overlap with legal requirements. For service businesses relying on repeat revenue, respecting consent isn't just about avoiding fines; it's about building trust. When customers know they’ve genuinely opted in, they’re more likely to engage—turning compliance into a foundation for stronger, permission-based relationships.

How CallMyCustomers Ensures Compliant Reactivation Campaigns for US Service Businesses

CallMyCustomers ensures compliant reactivation campaigns by anchoring every outreach in explicit, verifiable consent—aligning with both U.S. CAN-SPAM requirements and global opt-in standards like GDPR and CASL. The company begins by reviewing and segmenting client lists based on recency, past interactions, and service history, ensuring only legitimate customer data is used for reactivation efforts. Before any message is sent, clients approve all scripts, offers, and content, maintaining full control over what communicates on their behalf. This permission-based model directly addresses the core legal principle that sending promotional emails without consent is illegal in most jurisdictions, where regulations like GDPR and CASL require explicit opt-in before any marketing communication can occur.

For U.S.-based recipients, CallMyCustomers adheres to CAN-SPAM’s opt-out framework by including accurate sender information, a valid physical address, and a functional unsubscribe mechanism in every email—honoring opt-out requests within 10 business days as legally required. The company further strengthens compliance by implementing double opt-in processes where appropriate, recognizing it as the “gold standard for compliance” under GDPR and a best practice for verifiable consent across regions. All email campaigns are sent with proper authentication (SPF/DKIM/DMARC) to meet deliverability standards enforced by providers like Gmail, which since February 2024 has permanently rejected bulk senders lacking these technical safeguards or a working one-click unsubscribe link.

In health-sector verticals such as dental, med spa, and wellness clinics, CallMyCustomers operates under strict privacy protocols, including HIPAA-compliant handling of protected health information and separate written authorization for any marketing content containing PHI. Outreach to these clients occurs only under valid business associate agreements (BAAs) and with messaging that meets clinical standards for patient communication. By combining client-approved messaging, immediate opt-out honoring, geographic list segmentation for global recipients, and rigorous consent tracking, CallMyCustomers turns reactivation into a repeatable, compliant revenue stream—helping US service businesses re-engage past customers without risking regulatory penalties or deliverability issues. This approach transforms compliance from a legal necessity into a trust-building advantage, ensuring every reactivation effort feels useful, not pushy.

Frequently Asked Questions

Is it actually illegal to send promotional emails without consent in the US?
Not exactly — the US CAN-SPAM Act uses an opt-out model, so you can send first without consent, but every commercial email must meet seven specific requirements including accurate sender info, a physical address, and a working unsubscribe. The catch is that penalties run $53,088 per violating email — per message, not per campaign.
Do I need consent before emailing customers in other countries?
Yes — the law follows your recipient, not your company address. Emailing someone in Germany triggers GDPR (fines up to €20 million or 4% of global revenue), and a recipient in Canada triggers CASL, which carries penalties up to $10 million CAD per violation and lets individuals sue directly.
Has anyone actually been fined for CAN-SPAM violations, or is this just theoretical?
Enforcement is very real: Verkada paid $2.95 million in 2024 — the largest CAN-SPAM settlement in FTC history — for sending 30 million emails with no opt-out and no physical address, and Experian settled for $650,000 over a broken unsubscribe flow during a platform migration. Over 300 CAN-SPAM cases have been filed with the FTC, and experts describe most violations as operational blind spots that quietly develop during redesigns or email platform switches.
How quickly do I have to honor unsubscribe requests?
Under CAN-SPAM you must process opt-out requests within 10 business days, keep the unsubscribe mechanism valid for at least 30 days after sending, and never charge a fee or require a login to opt out. You also remain legally responsible even when a third-party vendor sends the campaign on your behalf, per FTC guidance.
Is a pre-checked signup box enough to count as consent?
No — GDPR requires "clear, affirmative action," and pre-checked boxes are explicitly prohibited under EU law. German courts have even ruled that single opt-in is insufficient proof of consent in some cases, which is why double opt-in is considered the gold standard for compliance.
Can my emails get blocked even if I'm legally compliant?
Yes — since February 2024, Gmail has permanently rejected bulk senders who fail email authentication (SPF/DKIM/DMARC) or lack a working one-click unsubscribe, independent of any law. The good news is that good compliance habits and strong deliverability practices are basically the same thing — which is why permission-based outreach to real customers, like the approved campaigns CallMyCustomers runs, is both the safest and most profitable place to start.

Turn Compliance Into Your Competitive Edge

Sending promotional emails without proper consent isn't just a legal risk—it's a costly operational blind spot that can lead to fines exceeding $500 million for a single campaign, damaged deliverability, and eroded customer trust. Whether you're navigating CAN-SPAM in the U.S., GDPR in Europe, or CASL in Canada, the law follows your recipient, not your business location, making geographic segmentation and verifiable consent non-negotiable. For US service businesses, the safest and most profitable path forward is reactivating customers who already know and trust you—using explicit, approved outreach that turns compliance into a relationship-building advantage. If you'd like to see what your customer list could generate with a permission-based reactivation campaign, start with a free list review and get your rate and setup quoted upfront. Visit the insights hub to explore how compliant reactivation fits your repeat-revenue cycle.

Stay in the Loop